The White House moved to limit overseas access to Anthropic’s most powerful models. The dispute may reshape how governments control frontier AI exports.

On Friday, the White House, citing unspecified national security concerns, ordered Anthropic to limit the export of the powerful artificial intelligence models Fable and Mythos to individuals outside the United States, as well as to foreign nationals within the country.

Shortly after, Anthropic implemented access restrictions on both models, and they have been unavailable for about a week.

This case marked the first real test of whether the U.S. government can apply export controls to curb frontier AI in the same way it previously attempted to curb encryption and spyware, but with far more ambiguous results.

Although the situation sounds dramatic, the resolution of the dispute could determine not only Anthropic’s access to foreign markets but also the rules that other AI labs will need to shape.

Since Mythos launched in April, the company has positioned it as a potentially devastating cyber tool that could harm the Internet if spread too broadly – which is why, prior to the access ban, roughly 150 vetted companies and government bodies were allowed to use it.

Historical Context of Export Controls and Their Failures

The first significant example was the development of cryptography to protect data on the network, notably Pretty Good Privacy (PGP). The U.S. government initially viewed this tool as a dangerous ‘weapon’ that could impede intelligence agencies from intercepting emails, and launched a criminal investigation against the creator of PGP for alleged violations of export controls.

In response, the PGP source code was published in printed form by Phil Zimmermann, and the escalation of events unfolded, entering history as the Crypto War. The investigation was eventually dropped, allowing end-user encryption to be used at scale, notably on platforms such as Signal and WhatsApp.

In the early 2010s, researchers documented the use of Western-made spyware against dissidents in the Middle East, prompting several countries to agree to broaden the scope of the Wassenaar Arrangement – the international treaty governing the export of two types of dual-use software and technologies.

The idea was to classify spyware and other software as dual-use, forcing manufacturers to obtain export licenses for external customers in accordance with the terms of the agreement.

The Wassenaar Arrangement highlighted two vulnerabilities: a number of countries do not comply with the agreement, notably Israel, home to some of the most active spyware producers; and a reliance on purely national licensing regimes, where countries decide for themselves whether to allow exporting their products.

In Europe, despite several investigations and scandals, spyware export controls have not succeeded, and critics say that new efforts by EU member states are insufficient to curb the export of spyware to authoritarian regimes. Precedent cases have already shown that a number of companies relocate to jurisdictions with looser controls, while other regulatory chains remain imperfect.

While the debate continues, the conflict between Anthropic and the U.S. administration remains unresolved. There is a risk that the administration will concede to preserve the competitiveness of American companies on global markets, or, conversely, will require alignment with the government to access foreign clients, which could significantly affect costs and business models.

Given regulators’ past experience with dual-use technologies, export controls are unlikely to be the only effective strategy in countering the use of encryption and spyware for malicious purposes. Instead, a comprehensive mix of regulatory and technical measures is required that accounts for market dynamics and the development of new technologies.

Considering the evolution of regulatory practices in cybersecurity and artificial intelligence, further development of this topic will require more coordinated efforts among governments, academia, and industry to prevent abuse while not limiting technologies that benefit society and the economy.

In the context of global regulatory activity, modernization of approaches to controlling dual-use technologies remains an active topic: regulatory initiatives continue to adapt to rapid changes in the AI and cybersecurity fields, and practice shows that cooperation among governments, academia, and business is needed to reduce risks and support innovation.

In the future, advancing this topic will require more coordinated efforts to prevent abuse while not hindering technologies that can benefit society and the economy. Regional initiatives and international cooperation will remain key factors in crafting appropriate rules for the rapidly growing field of artificial intelligence.